CVE-2026-15581
Awaiting Analysis
Awaiting Analysis - Queue
TrustyAI Service Authentication Bypass Vulnerability
Vulnerability report for CVE-2026-15581, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-08-10
Last updated on: 2026-08-27
Assigner: redhat-SADP
Description
Description
A flaw was found in the TrustyAI Service (TAS) deployment. This vulnerability allows any pod on the cluster network to bypass authentication and directly access the TAS backend API. An attacker can exploit this to read, tamper with, or delete monitoring data and configurations, and inject arbitrary data into the service, potentially disrupting tenant operations.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| red_hat | trustyai_service | * |
| red_hat | red_hat_openshift_ai | 2.25.7 |
| red_hat | red_hat_openshift_ai | 3.3.5 |
| red_hat | red_hat_openshift_ai | 3.4.2 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-306 | The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. |